Active Directory Group Policy. Group Policy Overview  Successor to NT policies Much more flexible  Only applies to 2000 workstations Use old style policies.

Slides:



Advertisements
Similar presentations
Module 5: Creating and Configuring Group Policy
Advertisements

Khan Rashid Lesson 11-The Best Policy: Managing Computers and Users Through Group Policy.
Managing User Settings with Group Policy
Chapter 8 Configuring Group Policies
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 9: Implementing and Using Group Policy.
Chapter 9 Chapter 9: Managing Groups, Folders, Files, and Object Security.
Hands-On Microsoft Windows Server 2003 Administration Chapter 4 Managing Group Policy.
9.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
MIS Chapter 91 Ch. 9 – Implement and Use Group Policy MIS 431 – created Spring 2006.
10.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 9: Implementing and Using Group Policy.
Chapter 6: Configuring Security. Group Policy and LGPO Setting Options Software Installation not available with LGPOs Remote Installation Services Scripts.
Hands-On Microsoft Windows Server 2003 Administration Chapter 3 Administering Active Directory.
Lesson 16: Creating Group Policy Objects
7.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 7: Introducing Group Accounts.
Performing Software Installation with Group Policy
Guide to MCSE , Enhanced 1 Activity 9-1: Creating a Group Policy Object Using the MMC Objective: To create a GPO using the Group Policy Object Editor.
Understanding Group Policy on Windows Server 2003 John Howard, IT Pro Evangelist, Microsoft UK
9.1 © 2004 Pearson Education, Inc. Lesson 9: Implementing Group Policy in Windows 2000 Server Exam Microsoft® Windows® 2000 Directory Services Infrastructure.
9.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
MCTS Guide to Configuring Microsoft Windows Server 2008 Active Directory Chapter 3: Introducing Active Directory.
1 Chapter Overview Understanding Group Policies Implementing Group Policies Using Security Policies Troubleshooting Group Policy Problems.
Corso referenti S.I.R.A. – Modulo 2 07 – Group Policy 20/11 – 27/11 – 05/12 11/12 – 13/12 (gruppo 1) 12/12 – 15/12 (gruppo 2) Cristiano Gentili, Massimiliano.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 9: Implementing and Using Group Policy.
Using Group Policy to Manage User Environments. Overview Introduction to Managing User Environments Introduction to Administrative Templates Assigning.
Hands-On Microsoft Windows Server Security Enhancements in Windows Server 2008 Windows Server 2008 was created to emphasize security –Reduced attack.
Module 15: Manage the Windows ® Small Business Server 2008 Environment Using Group Policy.
70-411: Administering Windows Server 2012
11 MANAGING AND DISTRIBUTING SOFTWARE BY USING GROUP POLICY Chapter 5.
7.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 7: Introducing Group Accounts.
Managing User Desktops with Group Policy
Chapter 13 Users, Groups Profiles and Policies. Learning Objectives Understand Windows XP Professional user accounts Understand the different types of.
September 18, 2002 Windows 2000 Server Active Directory By Jerry Haggard.
Overview Introduction to Managing User Environments Introduction to Administrative Templates Using Administrative Templates in Group Policy Assigning Scripts.
Lesson 17-Windows 2000/Windows 2003 Server Security Issues.
Module 6: Implementing Group Policy. Overview Implementing Group Policy Objects Implementing GPOs in a Domain Managing the Deployment of Group Policy.
Introduction to Microsoft Management Console (MMC) MMC is a common console framework for management applications. MMC provides a common environment for.
11.1 © 2004 Pearson Education, Inc. Exam Designing a Microsoft ® Windows ® Server 2003 Active Directory and Network Infrastructure Lesson 11: Planning.
1 Chapter Overview Publishing Resources in Active Directory Service Redirecting Folders Using Group Policies Deploying Applications Using Group Policies.
Module 6: Configuring User Environments Using Group Policy.
Module 7 Configure User and Computer Environments By Using Group Policy.
Planning a Group Policy Management and Implementation Strategy Lesson 10.
Implementing Group Policy. Overview What is Group Policy Introduction to Group Policy Group Policy Structure How Group Policy Settings Are Applied in.
Module 4: Administration in Active Directory. Overview  Designing Active Directory to Delegate Administrative Authority Identifying Business Needs Identifying.
GPO - WINDOWS SERVER AGENDA: Introduction Group Policy Overview Types of Group Policies/Objects Associated Technologies How to implement.
4. Managing the Desktop Thomas Lee Chief Technologist – QA plc.
Configuring the User and Computer Environment Using Group Policy Lesson 8.
Section 11: Implementing Software Restriction Policies and AppLocker What Is a Software Restriction Policy? Creating a Software Restriction Policy Using.
Module 5: Implementing Group Policy
Page 1 System and Group Policies Lecture 7 Hassan Shuja 11/02/2004.
Section 4: Understanding the Architecture of Group Policy Processing Group Policy Components in AD DS Understanding the Group Policy Processing Sequence.
CN1276 Server Kemtis Kunanuraksapong MSIS with Distinction MCTS, MCDST, MCP, A+
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory, Enhanced Chapter 11: Group Policy for Corporate Policy.
Module 5: Creating and Configuring Group Policies.
Module 4 Planning for Group Policy. Module Overview Planning Group Policy Application Planning Group Policy Processing Planning the Management of Group.
1 Group Policies (Week 11, Monday 3/19/2007) © Abdou Illia, Spring 2007.
Administering Group Policy Chapter Eleven. Exam Objectives in this Chapter  Plan a Group Policy strategy using Resultant Set of Policy Planning mode.
Implementing Group Policy
© Wiley Inc All Rights Reserved. MCSE: Windows Server 2003 Active Directory Planning, Implementation, and Maintenance Study Guide, Second Edition.
Week 4 Objectives Overview of Group Policy Group Policy Processing Implementing a Central Store for Administrative Templates.
Implementing a Group Policy Infrastructure
11 INTRODUCTION TO GROUP POLICY Chapter 7. Chapter 7: INTRODUCTION TO GROUP POLICY2 WHAT CAN YOU DO WITH GROUP POLICY?  Control the user environment.
Module 6 Creating and Configuring Group Policy. Module Overview Overview of Group Policy Configuring the Scope of Group Policy Objects Evaluating the.
10.1 © 2004 Pearson Education, Inc. Lesson 10: Specifying Group Policy Settings Exam Microsoft® Windows® 2000 Directory Services Infrastructure.
Windows Server 2003 群組原則設定與管理 林寶森
Unit 8 NT1330 Client-Server Networking II Date: 2?10/2016
1.1 Microsoft® Windows® 2003 Server Group Policy Management Prof. Abdul Hameed.
Configuring the User and Computer Environment Using Group Policy Lesson 8.
Introduction to Group Policy Lesson 7. Group Policy Group Policy is a method of controlling settings across your network. – Group Policy consists of user.
Introduction to Group Policy
Presentation transcript:

Active Directory Group Policy

Group Policy Overview  Successor to NT policies Much more flexible  Only applies to 2000 workstations Use old style policies for NT  Used to manage desktop environment  Integrated into Active Directory

What Can Group Policy Manage?  Administrative Templates — registry-based settings  Security settings  Software installation  Scripts Login, logout, startup, shutdown  Folder redirection  Remote Installation Services  Internet Explorer maintenance

Registry-based Settings  Control over desktop, control panel access, Start Menu and Taskbar, some Windows components, and more…  Generally three settings — Not configured, Enabled, Disabled  Implemented via Administrative Templates Text file with.adm extension Extensible Can create your own Some programs ship with their own (Office)

Security Policy Settings  Account Policies — password, account, Kerberos  Local Policies — auditing, user rights, security options  Event Log — e.g. maximum size  Restricted Group — group membership  System Services — security and startup settings  Registry — registry key security  File System — file system security  Public Key Policies — encryped data, certificate authorities  IP Security Policies — IP security

Software Installation  Use to install software  Use to upgrade software  Three methods Assign applications to users Assign applications to computers Publish applications to users  Available to users, but not installed unless requested

Script Settings  Assign scripts (login, logout etc.)  Set processing order

Folder Redirection  Redirect special folders Start Menu, Desktop My Pictures, My Documents, Application Data  Choices No redirection Direct to same location Different locations based on security groups

Parts of Group Policy Objects  Each GPO has two sections Computer Configuration User Configuration  Each part may be disabled Properties of GPO/General  Recommended — if a section is unused, disable it E.g. On GPO to configure user desktop, disable Computer Configuration section

Creating Group Policy Objects  AD Users and Computers Properties of Domain/OU Creates new GPO linked to that domain/OU  AD Sites and Services To create site GPO  Also via MMC Group Policy Snap-in To create a GPO not linked to a site, domain or OU

How are Group Policy Objects Applied  GPOs may be linked to AD containers Sites, Domains and Organizational Units (OUs) Apply to users and computers within container  Objects in child OUs inherit GPO settings from parent OUs, domain and site unless explicitly blocked  No inheritance across domain boundaries  One GPO may be linked to multiple containers  Multiple GPOs may be linked to a container  GPOs are not linked to groups

Modifying GPO Inheritance  Block Inheritance If enabled on a container, objects in container do not receive any GPO settings from parent containers  No Override If enabled on a GPO link, inheritance of GPO settings cannot be stopped via block inheritance NB Applied to link, not the GPO itself

Filtering Group Policy Settings  GPO settings applied to all objects in container  Filter using security groups Change default GPO permissions  Need Read and Apply GP ACEs to be able to apply a GPO  Need Read and Write GP ACEs to be able to read and modify a GPO

Deleting and Disabling Group Policy Objects  Disabling a GPO Disable Computer or User sections Disable both to disable GPO entirely Also disable using Options button in AD Users and Computers/Container Properties  Deleting a GPO AD Users and Computers Will be offered two options  Remove the link from the list — deletes link but not GPO  Remove the link and delete the GPO permanently — deletes GPO

Disabling and Inheriting:— What do the Properties Belong to?  Properties of a given GPO Disable Computer Configuration Settings Disable User Configuration Settings  Properties of a given container Block policy inheritance  Properties of a given link No override Disabled: the GPO is not applied to this container

Storage of Group Policy Objects  Group Policy Container (GPC) Active Directory object storing version, status etc. View by enabling Advanced Features in AD Users and Computers, then System/Policies Named by GUID  Group Policy Template (GPT) Sysvol\Policies folder Contains all GP) settings Named by GUID  GPC and GPT replicated separately  Policies only apply if both GPC and GPT are in sync

Storage of Group Policy Settings  Stored in client registry HKEY_LOCAL_MACHINE (Computer settings) HKEY_CURRENT_USER (User settings)  Special registry keys used \Software\Policies (preferred) \Software\Microsoft\Windows\CurrentVersion\Policies  Removed when GPO no longer applies

Order of GPO Application  Order of application is Site, Domain OU (SDOU)  Multiple OUs — order of application is according to domain hierarchy (start at top of tree and work down)  Multiple GPOs for same OU — processed in reverse order of list of GPOs shown for that OU I.e. GPO at top of list takes precedence Order can be changed

When are GP Settings Applied?  Computer settings On boot According to periodic refresh cycle  User settings On user logon According to periodic refresh cycle  If computer and user settings conflict, computer settings take precedence

Refreshing Group Policy  Default refresh intervals 2000 professional and member servers — very 90 minutes with randomized 30 minutes offset Domain controllers — every five minutes  Changed by altering administrative template settings for user or computers  Exception — software installation and folder redirection policies only applied on boot or user logon, not periodically

Conflicts  Where settings for GPO of parent container conflict with those for GPO of child, child container settings win  Where settings from different GPOs linked to same container conflict, settings of GPO highest in list are win Use Up/Down to change position  Exception — where computer and user settings conflict, computer settings win Except IP Security and User Rights settings

Managing Group Policy Objects  Creating or editing GPOs controlled by PDC emulator by default Minimise conflicts  To change Group Policy mmc snap-in/View/DC Options Or use Group Policy  Recommended that this is left unchanged  NB By default, only Domain Admins, Enterprise Admins, Group Policy Creator Owners and System account can create and edit GPOs

Loopback Processing  Computer settings part of GPO linked to OU apply only to computers within OU  Similarly, user settings apply only to users within OU  Therefore, normally, user in OU A logging on to computer in OU B gets combination of user settings from OU A GPOs and computer settings from OU B GPOs (and any inherited etc.)

Loopback Processing cont.  May want to apply same user settings to any user logging on to a given workstation, regardless of user OU E.g. classroom, public area workstations  Loopback processing does this Merge mode applies normal GPOs for user as well (but those from computer take precedence) Replace mode does not apply normal GPOs for user

Local Group Policy  Computers also have a single Local Group Policy Object (LGPO)  Only supports Security Settings, Administrative Templates and Scripts  Processed before AD GPOs Block inheritance does not stop its application  Generally unused in an AD setup Most useful for configuring standalone computers

Delegation  It is possible to delegate responsibility for the following tasks Managing links Creating GPOs Editing GPOs

DomainExceptions for Domain Controllers  Some settings only from GPOs linked to domain Domain controllers share same account database so some settings must be the same Not applied to Domain Controllers OU because DCs may be moved out of this OU  NB Can change these settings in other GPOs but will have no effect on domain policy Will affect local logons (i.e. non-domain) if they apply to workstations or member servers

Exceptions for Domain Controllers cont.  Domain-wide settings All account policies (Computer Configuration/Windows Settings/Security Settings)  I.e. Password, Account lockout and Kerberos policies) Some settings from Computer Configuration/Windows Settings/Local Policies/Security Options  Automatically log off users when logon time expires  Rename administrator account  Rename guest account

Common Desktop Management Scenarios  Package containing GPOs developed for six different scenarios that can be loaded into AD Includes white paper describing scenarios Excel spreadsheet documenting all GPO settings  Scenarios are for the following Lightly Managed Desktop (e.g. power user) Mobile User Multi-User Desktop AppStation (Highly Managed Desktop) (e.g. admin user) TaskStation (e.g. single task) Kiosk (e.g. public workstation)

Common Desktop Management Scenarios  NB Loading GPOs into AD does not mean they take immediate effect Not linked to any container  Use as starting points  Use Excel spreadsheet to document GPO changes

Common Desktop Management Scenarios  White paper url=/TechNet/prodtechnol/windows2000serv/deploy/grp polsc.asp url=/TechNet/prodtechnol/windows2000serv/deploy/grp polsc.asp  All files polscen.exe polscen.exe

OU Design Issues  Deep OU structure Easier to apply GPOs without filtering More likely to require inheritance modifications  Flat OU structure More likely to need filtering Easier to troubleshoot (less inheritance issues)

Number of GPOs Required  Few comprehensive GPOs Less to manage Shorter logon times  Many narrowly focussed GPOs More to manage Likely to need to more filtering Increased logon times  In theory, up to 20 GPOs applying to a user should not have major impact on logon times

Recommendations  Disable unused parts of GPO (computer, user settings)  Limit use of inheritance blocking, no override, loopback processing and filtering Simplifies troubleshooting  Limit total number of GPOs that apply to a user or computer Improves logon times

Recommendations cont.  Limit the number of admins who can edit GPOs  Test thoroughly before applying to users/computers  Document settings Use spreadsheets from Common Desktop Management Scenarios package

References  Windows 2000 Group Policy wp.doc wp.doc  Loopback Processing of Group Policy 87.ASP 87.ASP  How to Use Group Policy Objects to Deploy SP1 for Windows ASP 01.ASP

References  Group Policy Application Rules for Domain Controllers 76.ASP 76.ASP  Domain Security Policy in Windows ASP 30.ASP  Configuring Account Policies in Active Directory 50.ASP 50.ASP

Diagnosing Problems  Resource kit Gpotool.exe Gpresult.exe  FAZAM 2000 Help to see end results of applying a number of GPOs ng/fazam2000-o.asp ng/fazam2000-o.asp  Reduced functionality version  Full, commercial version